Coldcard firmware exploit drives bitcoin holders back to exchanges

Editorial illustration for: Coldcard exploit drives smaller bitcoin holders to exchanges, reversing FTX-era self-custody trend

In brief

  • Coldcard firmware bug weakened seed phrase generation, affecting 1,000+ addresses since July 30
  • Bitcoin exchange deposits under 10 BTC spiked to 7,300 BTC on July 31, highest since February
  • Retail holders moved coins to exchanges for safety, reversing post-FTX self-custody migration
  • Major exchanges received 11,163 BTC net inflows on July 31 across Binance, River, Kraken, OKX

The Coldcard Vulnerability

Coldcard is a Bitcoin-only hardware wallet made by Canadian firm Coinkite. A firmware bug weakened seed phrase generation, causing some devices to fall back on a predictable software random number generator instead of the device's hardware RNG. The thefts began on Friday, July 30, with losses tracked across more than 1,000 addresses totaling roughly $70–$90 million.

The response from retail investors was swift. On July 31, daily bitcoin deposits to exchanges in transactions under 10 BTC jumped to 7,300 BTC, the highest level since February 6. This wasn't panic selling—it was a move toward perceived safety on centralized platforms.

Reversing the Post-FTX Trend

The shift stands in stark contrast to what happened after November 2022. Following the FTX collapse, investors rushed to withdraw large volumes of coins from centralized exchanges into self-custody solutions including hardware wallets. That migration reflected a loss of faith in exchange solvency. This time, the threat isn't exchange insolvency—it's hardware wallet vulnerability.

The number of daily active Bitcoin addresses spiked from 645,000 on July 30 to almost one million on July 31, the highest since December 10, 2024. The combined volume of all transfers smaller than 1 BTC reached 39,600 BTC on Friday, nearly matching the 39,900 BTC moved on November 16, 2022, the day after FTX filed for bankruptcy.

"Daily exchange deposits of Bitcoin transfers < 10 BTC spiked yesterday [Friday] to 7.3K BTC, the highest since February 6. Could be related to the coldcard hack, as people move their holdings looking for safety"

— Julio Moreno, head of research at CryptoQuant

Exchange Inflows Accelerate

Total net inflows to exchanges totaled 11,163 BTC on July 31, most of which flowed into major exchanges and firms like Binance, River, Kraken, and OKX. The total number of BTC held in wallets tied to centralized exchanges increased to 2.715 million from 2.703837 million before the Coldcard exploit.

The pattern reveals a nuanced market: retail holders aren't abandoning self-custody as a principle. They're responding to a specific, acute threat by moving smaller balances to platforms they trust in the moment. Whether this inflow persists depends on how quickly Coldcard resolves the vulnerability and restores confidence in hardware-based key management.

Frequently asked questions

What caused the Coldcard exploit?

A firmware bug in Coldcard hardware wallets weakened seed phrase generation, causing some devices to fall back on a predictable software random number generator instead of the device's hardware RNG. The thefts began July 30 and affected over 1,000 addresses.

Why are bitcoin holders moving coins to exchanges?

Retail holders are moving smaller balances onto centralized exchanges out of caution following the Coldcard vulnerability. This is a temporary safety measure in response to hardware wallet risk, not a loss of faith in self-custody as a principle.

How is this different from the FTX collapse?

After FTX collapsed in November 2022, investors moved coins from exchanges into self-custody to avoid exchange insolvency risk. The Coldcard exploit reverses this: it's a self-custody vulnerability driving holders back to exchanges they trust.